A podcast offering news, views and commentary on security issues for Voice Over IP(VoIP), Unified Communications (UC) and IP Telephony

Greetings! Welcome to our little corner of the online world where, from 2005-2008, once a week (roughly) we got together to have a conversation about Voice-over-IP (VoIP) security. As you look down the page, you'll see that we have two general types of shows. Our "main" shows are where we get together and discuss the latest VoIP security news, offer commentary on topical issues and play and respond to listener comments. These shows have been numbered consecutively since our start in October 2005 and generally run about 45 minutes. Our "Special Edition" podcasts (now designated with a "SE" in the show title) are typically special interviews we have done, presentations we have given or panels/presentations from conferences that we have been able to record. They are quite diverse and so do vary widely in length. As you'll notice in our main shows, we've developed a wonderful community of listeners and always welcome comments, contributions or other feedback. Thank you for visiting and we hope you enjoy the shows. Please do send us your thoughts and comments.

April 30, 2013

Last week I recorded the first "Blue Box: Special Edition" interview that I have recorded in several years... and so I just wanted to give anyone reading the heads-up that a new episode may be appearing in your RSS feed soon - after a 3.5 year hiatus! :-)
We're not bringing back the full show... yet, anyway... but I have a couple of interviews relating to VoIP security that I'm going to run through the Blue Box podcast feed.
I hope you enjoy them... and if you have ideas for interviews you think I should consider, please feel free to send me email (although be warned I don't check it all that regularly so a response may be a bit delayed).

September 24, 2012

I'm pleased to note that all Blue Box podcast episodes are now available again. As I mentioned yesterday, it was purely an administrative issue with the payment method.

For those curious, this show is a prime example of the "Long Tail" of content on the Web - even though we haven't produced a new "real" show since #85 on October 23, 2008, we still see anywhere from 30-100 downloads of various Blue Box shows every day. People are finding the show through various search terms and listening to the episodes.

Perhaps somewhat sadly this is also a commentary on how relevant some of the same VoIP security issues we discussed from 2005-2008 still are today in 2012!

My apologies, again, to anyone who tried listening over the past weekend when the show was offline. Thank you for the interest and for I hope that you find our past episodes educational and useful.

September 23, 2012

If you are trying to listen to any of our old Blue Box shows, unfortunately it seems I missed an email alert and the payment method expired for the service I use to host the media files. I am in communication with their billing department now and expect to have the matter cleared up tomorrow with the shows available again.

My apologies to anyone who was trying to listen to one of the shows. I will get them back online as soon as I can.

July 15, 2010

For those of you listening to Blue Box, you may be interested to know that I (Dan) recently wrote a book for Syngress called the "Seven Deadliest Unified Communications Attacks". In the book, I discuss the common theme that Jonathan and I have talked about on the show of needing to look at communications security at a higher-level, more "holistic" level. It's not enough just to think about the security of your IP-PBX... you also have to think about the security of your mail servers, your firewalls, your databases, etc.

You also have to think beyond voice to also including instant messaging/IM, video, presence, mobile devices and more. And... you have to think about them in the context of a globally-distributed IP infrastructure.

Information about the book and links to resources mentioned in the book are available from the books website:

I am working on getting permission to run those both as Blue Box Special Editions (I have approval on the VUC session).

In many ways, much of the book came out of the three years of great conversations that Jonathan and I had with so many of you - and I have to thank all of you who have participated in the Blue Box community over the years for your questions, your comments and all the feedback. I hope you will find that this book continues that dialogue and discussion about how to secure our communications networks.

Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-415-830-5439 or via SIP to 'bluebox@voipuser.org' to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

April 07, 2009

Just testing Twitter integration... I have a growing suspicion that TypePad only notifies Twitter if you write your post online using TypePad's interface. But of course, I don't. I write almost all my posts offline using the MarsEdit editor. Let's see if this shows up in http://twitter.com/blueboxpodcast

March 09, 2009

Last week at the Emerging Communications Conference (eComm) 2009 in San Francisco, a remarkable event happened: Jonathan Zar, Martyn Davies, and I (Dan York) all wound up at the same place at the same time. Over the 3.5 years since we started Blue Box back in October 2005, Jonathan and I have met at events, Martyn and I have met and Jonathan and Martyn have met. But the three of us had never been together at the same place.

Now the particular place we met was a "Dev Dinner" hosted by (my employer) Voxeo after the end of eComm - and we had some great conversations along with the food. Martyn produced his camera and we did record the actual event:

Alas, it was too noisy there for us to do any actual recording, but it was great to have all three of us there. For those who may not recall the history, Martyn was one of our earliest listeners and is the person who provided both the image that we use for Blue Box (in iTunes, in the MP3 file, etc.) and also the music that we use for the intro and outro. He's also guest-hosted several times and contributed a couple of interviews over the years.

January 23, 2009

If you will be in Miami at ITEXPO February 2-4 you are welcome to attend a free "SIP Trunking And Security" session I (Dan York) will be doing as part of Ingate Systems' SIP Trunking Workshops. The SIP trunking workshops are free to all attendees even if you only register for an exhibit pass.

My session will be 11:15-12:30 on Wednesday, February 3rd, and if you do attend please feel free to come up and introduce yourself (or drop me a note in advance to let me know to look out for you). I'll be bringing my recording gear, too, and the talk will eventually go out in my Blue Box Podcast feed so you will be able to hear it later.

P.S. If you are attending ITEXPO and your company makes a product or provides a service related to VoIP security, please feel free to let me know and perhaps we can schedule an interview to go out as a Blue Box Special Edition.

November 18, 2008

For those of you who may be used to reading this blog through the "Security Bloggers Network" set up originally by Alan Shimel, you need to be aware that the "SBN" is going through a transition. As Alan details on his blog, Google is in the process of shutting down the "Network" feature of Feedburner and as a result the page and feed for the SBN will be going away.

Alan is working on a new solution but in the meantime you may want to grab the OPML file for the Security Bloggers Network (you should then be able to import this into most feed readers). There are a lot of great security blogs out there.

Stay tuned for more information - once Alan has another solution in place I'll post an update.

October 27, 2008

It looks like FeedBurner finally refreshed its DNS info and the RSS feed is back in action. My apologies for the interruption. Please do let me know if there is anything else strange going on with the website or feed. Thanks.

October 26, 2008

Ah, the joys of switching domain name providers. I transferred blueboxpodcast.com from one registrar to another last week shortly before the domain name was set to expire. Unfortunately, I made one serious mistake - I didn't check the DNS nameservers for the domain at the new registrar (GoDaddy) to ensure they were pointing to the new nameservers. They weren't... they will still pointing to the old nameservers. As a result, when the domain name expired at the end of the day on Friday, the web site was no longer available and had the message that the domain name had expired.

MANY THANKS to the couple of you who contacted me on Saturday to let me know about this!

So I fixed the web site yesterday morning so that "www.blueboxpodcast.com" pointed over to TypePad, where I host this site, and that all seems to be back in action. If you type in "blueboxpodcast.com" without the "www", it was going to a generic GoDaddy page but I've set up the forwarding now so that this should now redirect you to www.blueboxpodcast.com once the DNS propagation occurs.

What is still dead, though, is the RSS feed... which is rather annoying since that is what podcast subscription tools like iTunes use! In working through the issues this morning, it appears to be the issue that

So it appears that I'm waiting for FeedBurner to update its DNS. I've tried all sorts of options in the FeedBurner settings, including the "Resync Feed" but nothing works because it seems that it is unable to get to the new site (because of DNS).

I've filed a help request in the FeedBurner Google Group (which appears to be the only way to get help). Hopefully FeedBurner will age out its DNS info soon and the feed will be back in action.

What I find strange, though, is that I'm 99% sure that all the DNS records had a TTL of 1 hour (and I'm 100% positive the new ones do). So my question to FeedBurner is - if that is the case, why aren't they respected the TTL settings of the domains?

October 24, 2008

Today is a special day for me. It was three years ago on October 24, 2005, that Blue Box Podcast #1 was uploaded. It was an 11-minute episode where I talked about... Skype security, SIP security, IETF, VOIPSA and some other VoIP security news..... (Hmmm... sounds lot like our recent shows, too, eh?)

Jonathan Zar joined me a week later on Blue Box Podcast #2 and we've been going ever since. We've now produced over 112 episodes, had close to 245,000 downloads of our various shows, met some amazing people, learned a lot along the way... and hopefully helped you all learn a lot out there as well.

Thank you to all of you who have joined with us on this journey... whether you've listened to our show from the very beginning (and we know of a couple of you who have) or have only recently joined in... thank you!

Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-415-830-5439 or via SIP to 'bluebox@voipuser.org' to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

October 20, 2008

It was three years ago Friday, on October 24, 2005, that I uploaded Blue Box Podcast #1, an 11-minute show where I introduced the show, talked about VoIP security news (To no surprise, I was talking about Skype security!), some projects of VOIPSA and some other podcasts people might find interesting. A week later, on Halloween 2005, Jonathan joined me in Blue Box Podcast #2 and we were off and running...

Three years later... 84 main Blue Box episodes (with one more recorded) .... 26 Special Editions (with about 10 in the queue)... almost 250,000 downloads... we're still here and, with an admitted bit of a rough patch this summer, are still going along creating shows and enjoying what we do.

Jonathan and I are planning to record a 3-year show on this coming Friday, October 24th, and if you have any comments you would like us to include in that show, please do get them to us by the end of the day on Thursday, October 23rd. You can send them to us via:

The show started out 3 years ago as really an experiment in seeing whether or not podcasting could be used to reach out to very specific audiences... and it's been both fun, amazing and interesting to see how well it's done.

Thank you to all of you who have continued to listen and contribute over the years!

Full Disclosure

Jonathan Zar is affiliated with Pingalo and is the Secretary of VOIPSA and member of the Board of Directors.

This is a personal project and neither the Internet Society, Pingalo nor VOIPSA have any formal connection to this podcast. In the interest of transparency we just thought you should know our affiliations.

Why "Blue Box"?

We chose the name "Blue Box" primarily as a nod to the era of phone phreaking in part to illustrate that threats to telephony are not new - they just continue to change and evolve. That and admittedly the name just sounded cool.